Логотип exploitDog
bind:CVE-2023-23625
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-23625

Количество 2

Количество 2

nvd логотип

CVE-2023-23625

почти 3 года назад

go-unixfs is an implementation of a unix-like filesystem on top of an ipld merkledag. Trying to read malformed HAMT sharded directories can cause panics and virtual memory leaks. If you are reading untrusted user input, an attacker can then trigger a panic. This is caused by bogus `fanout` parameter in the HAMT directory nodes. Users are advised to upgrade to version 0.4.3 to resolve this issue. Users unable to upgrade should not feed untrusted user data to the decoding functions.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-q264-w97q-q778

почти 3 года назад

Denial of service via HAMT Decoding Panics

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-23625

go-unixfs is an implementation of a unix-like filesystem on top of an ipld merkledag. Trying to read malformed HAMT sharded directories can cause panics and virtual memory leaks. If you are reading untrusted user input, an attacker can then trigger a panic. This is caused by bogus `fanout` parameter in the HAMT directory nodes. Users are advised to upgrade to version 0.4.3 to resolve this issue. Users unable to upgrade should not feed untrusted user data to the decoding functions.

CVSS3: 5.9
0%
Низкий
почти 3 года назад
github логотип
GHSA-q264-w97q-q778

Denial of service via HAMT Decoding Panics

CVSS3: 5.9
0%
Низкий
почти 3 года назад

Уязвимостей на страницу